peter bassill · operator
$ cve CVE-2021-20028 JSON

CVE-2021-20028 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 30.1% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-18.

Description

Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS30.08% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-89
On CISA KEVyes — remediate by 2022-04-18
Public exploitnone known
Published2021-08-04
Last modified2026-06-17

CISA KEV

NameSonicWall Secure Remote Access (SRA) SQL Injection Vulnerability
Added2022-03-28
Due2022-04-18
Vendor / productSonicWall / Secure Remote Access (SRA)
Ransomware useknown

Affected (12)

VendorProduct
sonicwallsma 210
sonicwallsma 210 firmware
sonicwallsma 410
sonicwallsma 410 firmware
sonicwallsma 500v
sonicwallsma 500v firmware
sonicwallsra 1600
sonicwallsra 1600 firmware
sonicwallsra 4600
sonicwallsra 4600 firmware
sonicwallsra va
sonicwallsra va firmware

References

→ the Explorer  ·  watch your stack  ·  NVD